The furore surrounding the recent cyber-attacks in the UK retail sector has attracted a great deal of attention and has focused nearly every company to think about their own cyber security posture. But can we say that the major retail giants, Marks & Spencer (M&S), Harrods, and the Co-op who were targeted have poor or limited cyber security measures in place? The answer is probably no, so why were the attacks so successful?
We know that these targeted attacks were reportedly carried out by a hacking group known as "Scattered Spider," which used DragonForce ransomware to encrypt and effectively lock IT systems, resulting in major outages and significant financial losses (potentially £1Bn for M&S). Of course, these companies would have invested in market leading IT Security products (Antivirus, firewalls, E-mail and web protection) and Cyber Security services (incident logging, vulnerability management and incident response), but all these extensive services predominantly look for unauthorised or suspicious activity – but from what we have ascertained in these cases this kind of activity was not the case.
The attackers would have planned their attacks over a period of time, choosing their victims carefully, before choosing the right moment to strike. We know that the key attack methods used to gain authorised access to these networks, and thus not arouse suspicion, were:
Social Engineering:
Multi-Factor Authentication (MFA) Fatigue:
Credential Abuse and Persistence:
Ransomware Deployment:
These incidents reinforce the message that cyber security is not just about having the best technological defences in place but must include having robust training, good processes and an understanding of the cyber risks that we face.
What do we do next?
It is important that organisations understand that these types of attack methods are not new and that taking cyber security for granted can often make the attack so much easier for the attacker. At CSA Cyber our team of professionals have been working with our clients to help check or implement the following tasks:
Final Thoughts
These methods highlight the attackers' reliance on exploiting human error and leveraging existing vulnerabilities rather than introducing new ones. The incidents underscore the importance of robust cyber security measures, including working with outsourced providers such as CSA Cyber. At CSA, our experts provide a comprehensive selection of Offensive Security and SOC services, from Social Engineering & Phishing Simulation services to Managed Detection & Response (MDR), to keep you safe from cyber threats. To find out more, get in touch to see how we can secure your organisation.